Skip to main content

api-insecure Security Scan

View Release Notes
Securityv3.13.0Generated 2026-09-29 07:17:02 UTC
Critical
Clean
High
28 found
Scan Date
Sep 29, 2026

Scanner: Docker Scout

Critical vulnerabilities: 2

High vulnerabilities: 15

Medium vulnerabilities: 7

Critical

CVEPackageInstalledFixedDescription
CVE-2026-45833chromadb0.5.20not fixedCVE-2026-45833: Improper Control of Generation of Code ('Code Injection')
CVE-2026-39821stdlib1.26.51.26.6CVE-2026-39821

High

CVEPackageInstalledFixedDescription
CVE-2026-33818stdlib1.26.51.26.6CVE-2026-33818
CVE-2026-46600stdlib1.26.51.26.6CVE-2026-46600
CVE-2026-56853stdlib1.26.51.26.6CVE-2026-56853
CVE-2026-56855crypto0.55.00.56.0CVE-2026-56855
CVE-2026-56859stdlib1.26.51.26.6CVE-2026-56859
CVE-2026-56862stdlib1.26.51.26.6CVE-2026-56862
CVE-2026-57585msgpack1.1.21.2.1CVE-2026-57585
CVE-2026-78662crypto0.55.00.56.0CVE-2026-78662
GHSA-6v7p-g79w-8964msgpack1.1.21.2.1GHSA-6v7p-g79w-8964: Use After Free
CVE-2025-47273setuptools70.3.078.1.1CVE-2025-47273: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-81726nltk3.10.3not fixedCVE-2026-81726: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-84304grpc1.83.01.83.1CVE-2026-84304: Uncontrolled Resource Consumption
CVE-2026-84445grpc1.83.01.83.2CVE-2026-84445: Improper Validation of Array Index
CVE-2026-45830chromadb0.5.20not fixedCVE-2026-45830: Incorrect Privilege Assignment
CVE-2026-45831chromadb0.5.20not fixedCVE-2026-45831: Incorrect Authorization

Medium

CVEPackageInstalledFixedDescription
CVE-2026-85999soupsieve2.8.42.9.0CVE-2026-85999: Inefficient Regular Expression Complexity
CVE-2026-86000soupsieve2.8.42.9.0CVE-2026-86000: Inefficient Regular Expression Complexity
CVE-2023-49092rsa0.9.10not fixedCVE-2023-49092
CVE-2026-56860stdlib1.26.51.26.6CVE-2026-56860
CVE-2026-56858stdlib1.26.51.26.6CVE-2026-56858
CVE-2026-59890setuptools70.3.083.0.0CVE-2026-59890: Improper Handling of Unicode Encoding
CVE-2026-84303grpc1.83.01.83.1CVE-2026-84303: Improper Handling of Case Sensitivity
© 2026 Dify All rights reserved.Enterprise release information is confidential. Do not distribute externally.